I take things apart and write down what was inside. Stealers, loaders, RATs, and the crypter layer nearly every commodity payload hides behind.
Everything orbiting this core started as someone else's product. Whether a commercial RAT as dangerous as it claims. What a stealer's design gives away about the operators behind it. What Vidar looks like on its way out. Why nearly everything arrives wrapped in the same crypters — and why some threats are duller than their reputation. The writeups are the reviews.
Day to day I'm a SaaS Sales engineer working in cloud infrastructure and a sprinkle of DevSecOps, with a background in threat research and HUMINT. This side of the house is the research — the building lives on the dark side of this split. The Delphi habit crosses it: DarkGate pulled apart here, Delpheed built over there.
All of it is written from primary analysis. Where a claim can't be verified, it isn't made.